OPENSUSE-SU-2021:3672-1
Not scored
Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2021-30640: Escape parameters in JNDI Realm queries (bsc#1188279). - CVE-2021-33037: Process T-E header from both HTTP 1.0 and HTTP 1.1. clients (bsc#1188278). - CVE-2021-41079: Fixed a denial of service caused by an unexpected TLS packet (bsc#1190558).
Exploit probability
Not scored
Published
November 16, 2021
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
openSUSE-SU-2021:3672-1
View original source
This update for tomcat fixes the following issues: - CVE-2021-30640: Escape parameters in JNDI Realm queries (bsc#1188279). - CVE-2021-33037: Process T-E header from both HTTP 1.0 and HTTP 1.1. clients (bsc#1188278). - CVE-2021-41079: Fixed a denial of service caused by an unexpected TLS packet (bsc#1190558).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188278
- https://bugzilla.suse.com/1188279
- https://bugzilla.suse.com/1190558
- https://lists.opensuse.org/archives/list/[email protected]/thread/5JSV3IQW2IZ4TG73GE2HYEJN52YYLT3T/
- https://www.suse.com/security/cve/CVE-2021-30640
- https://www.suse.com/security/cve/CVE-2021-33037
- https://www.suse.com/security/cve/CVE-2021-41079